[Q14-Q39] GCP-SOE-B Certification Exam Dumps Questions in here [Sep-2026]

Share

GCP-SOE-B Certification Exam Dumps Questions in here [Sep-2026]

Updated GCP-SOE-B Exam Practice Test Questions

NEW QUESTION # 14
You are an incident response engineer at an organization that uses Google Security Operations (SecOps). You recently started monitoring IOCS in Applied Threat Intelligence using YARA-L rules. You have discovered that there are more false positive alerts than expected, which is causing noise for the SOC team. You need to reduce the number of false positive alerts. What should you do?

  • A. Implement curated detections instead of custom YARA-L rules.
  • B. Configure alert grouping for the most repetitive alerts.
  • C. Modify the YARA-L rules to use an indicator confidence score (IC-Score) of 60% and above.
  • D. Create a playbook that automatically tunes the IOC source if its indicator confidence score (IC- Score) is between 60% and 80%.

Answer: C


NEW QUESTION # 15
You are a SOC manager guiding an implementation of your existing incident response plan (IRP) into Google Security Operations (SecOps). You need to capture time duration data for each of the case stages. You want your solution to minimize maintenance overhead. What should you do?

  • A. Create a Google SecOps SOAR dashboard that displays specific actions that have been run, identifies which stage a case is in, and calculates the time elapsed since the start of the case.
  • B. Configure a detection rule in SIEM Rules & Detections to include logic to capture the event fields for each case with the relevant stage metrics.
  • C. Configure Case Stages in the Google SecOps SOAR settings, and use the Change Case Stage action in your playbooks that captures time metrics when the stage changes.
  • D. Write a job in the IDE that runs frequently to check the progress of each case and updates the notes with timestamps to reflect when these changes were identified.

Answer: C


NEW QUESTION # 16
You are responsible for managing threat intelligence and IOC lists in your organization. You have compiled a list of IOCS from recent incidents. You want to quickly and efficiently share the IOCs with other teams for collaboration and integration into their operational processes. What should you do?

  • A. Add the IOCs to a collection in Google Threat Intelligence, and share the collection with the other teams.
  • B. Create a list in Google Security Operations (SecOps), and grant the required access to the other teams.
  • C. Export the IOCS from Google Threat Intelligence in CSV or JSON format, and email the file to the other teams.
  • D. Create a new threat graph in Google Threat Intelligence, and share the graph with the other teams.

Answer: B


NEW QUESTION # 17
You work for an organization that operates an ecommerce platform. You have identified a remote shell on your company's web host. The existing incident response playbook is outdated and lacks specific procedures for handling this attack. You want to create a new, functional playbook that can be deployed as soon as possible by junior analysts. You plan to use available tools in Google Security Operations (SecOps) to streamline the playbook creation process. What should you do?

  • A. Use the playbook creation feature in Gemini, and enter details about the intended objectives. Add the necessary customizations for your environment, and test the generated playbook against a simulated remote shell alert.
  • B. Use Gemini to generate a playbook based on a template from a standard incident response plan and implement automated scripts to filter network traffic based on known malicious IP addresses.
  • C. Create a new custom playbook based on industry best practices, and work with an offensive security team to test the playbook against a simulated remote shell alert.
  • D. Add instruction actions to the existing incident response playbook that include updated procedures with steps that should be completed. Have a senior analyst build out the playbook to include those new procedures.

Answer: A


NEW QUESTION # 18
Your team has onboarded a new log source from a third-party DNS filtering solution. After ingestion, you observe that key UDM fields such as network.dns.questions.name and metadata.product_event_type are missing from the parsed events in Google Security Operations (SecOps). You suspect that the default parser does not fully align with the source format. You need to ensure these fields are available for downstream detection rules that rely on DNS query telemetry and event categorization. What should you do?

  • A. Enable asset enrichment for the log source to infer missing fields based on correlated host activity.
  • B. Use a custom parser that outputs all fields as raw JSON for detection.
  • C. Create a parser extension that maps the missing source fields to the correct UDM fields and attach it to the existing parser.
  • D. Modify the ingestion source definition to remap raw fields directly to UDM by using the UDM sample output.

Answer: C


NEW QUESTION # 19
You have been tasked with creating a YARA-L detection rule in Google Security Operations (SecOps). The rule should identify when an internal host initiates a network connection to an external IP address that the Applied Threat Intelligence Fusion Feed associates with indicators attributed to a specific Advanced Persistent Threat 41 (APT41) threat group. You need to ensure that the external IP address is flagged if it has a documented relationship to other APT41 indicators within the Fusion Feed. How should you configure this YARA-L rule?

  • A. Configure the rule to trigger when the external IP address from the network connection event matches an entry in a manually pre-curated reference list of all APT41-related IP addresses.
  • B. Configure the rule to detect outbound network connections to the external IP address. Create a Google SecOps SOAR playbook that queries the Fusion Feed to determine if the IP address has an APT41 relationship.
  • C. Configure the rule to establish a join between the live network connection event and Fusion Feed data for the common external IP address. Filter the joined Fusion Feed data for explicit associations with the APT41 threat group or related indicators.
  • D. Configure the rule to check whether the external IP address from the network connection event has a high confidence score across any enabled threat intelligence feed.

Answer: C


NEW QUESTION # 20
You are responsible for evaluating the level of effort required to integrate a new third-party endpoint detection tool with Google Security Operations (SecOps). Your organization's leadership wants to minimize customization for the new tool for faster deployment. You need to verify that the Google SecOps SOAR and SIEM support the expected workflows for the new third-party tool.
You must recommend a tool to your leadership team as quickly as possible. What should you do? (Choose two.)

  • A. Configure a Pub/Sub topic to ingest raw logs from the third-party tool and build custom YARA-L rules in Google SecOps to extract relevant security events.
  • B. Develop a custom integration that uses Python scripts and Cloud Run functions to forward logs and orchestrate actions between the third-party tool and Google SecOps.
  • C. Review the architecture of the tool to identify the cloud provider that hosts the tool.
  • D. Identify the tool in the Google SecOps Marketplace and verify support for the necessary actions in the workflow.
  • E. Review the documentation to identify if default parsers exist for the tool, and determine whether the logs are supported and able to be ingested.

Answer: E


NEW QUESTION # 21
Your organization's Google Security Operations (SecOps) tenant is ingesting a vendor's firewall logs in its default JSON format using the Google-provided parser for that log. The vendor recently released a patch that introduces a new field and renames an existing field in the logs. The parser does not recognize these two fields and they remain available only in the raw logs, while the rest of the log is parsed normally. You need to resolve this logging issue as soon as possible while minimizing the overall change management impact. What should you do?

  • A. Use the Extract Additional Fields tool in Google SecOps to convert the raw log entries to additional fields.
  • B. Use the web interface-based custom parser feature in Google SecOps to copy the parser, and modify it to map both fields to UDM.
  • C. Deploy a third-party data pipeline management tool to ingest the logs, and transform the updated fields into fields supported by the default parser.
  • D. Write a code snippet, and deploy it in a parser extension to map both fields to UDM.

Answer: A


NEW QUESTION # 22
You are a security analyst at an organization that uses Google Security Operations (SecOps). You have identified a new IP address that is known to be used by a malicious threat actor to launch network attacks. You need to search for this IP address in Google SecOps using all normalized logs to determine whether any malicious activity has occurred. You want to use the most effective approach. What should you do?

  • A. Write UDM searches using YARA-L 2.0 syntax to find events where the IP address appears.
  • B. On the Alerts & IOCS page, review results and entries where the IP address appears.
  • C. Write a YARA-L 2.0 detection rule that searches for events with the IP address.
  • D. Run raw log searches using the IP address as a search term.

Answer: A


NEW QUESTION # 23
You are responsible for developing and configuring data ingestion in Google Security Operations (SecOps) for your organization. Your organization is using a prebuilt parser to parse a complex but stable and common log source. The parser is working correctly. However, your organization now wants you to change the configuration to parse additional fields from the raw logs and map them to UDM fields. What should you do?

  • A. Design and develop a custom parser.
  • B. Apply any pending updates to the prebuilt parser.
  • C. Implement middleware to modify the underlying data structure.
  • D. Implement a parser extension on top of the prebuilt parser.

Answer: D


NEW QUESTION # 24
You are working with your company's analyst team to automate the investigation of phishing alerts ingested directly into Google Security Operations (SecOps) SOAR from an email inbox.
The analyst team currently uses a SIEM query to search for related information. You need to design a solution to automatically include the query results in the Google SecOps case without writing any new code. What should you do?

  • A. Modify the detection rule in the SIEM to include the query results as part of the detection.
  • B. Add a widget to the Default Case View in Google SecOps SOAR that allows the analyst team to query directly from the widget.
  • C. Create a custom action in Google SecOps IDE that runs the SIEM query from a playbook through an API call and returns the results.
  • D. Add an action to the playbook that runs the SIEM query and returns the results.

Answer: D


NEW QUESTION # 25
An organization detects a successful login to a Google Cloud IAM user from an unfamiliar country, followed by the creation of multiple new service account keys within minutes. No malware alerts are triggered. What is the MOST appropriate immediate action?

  • A. Revoke active credentials, disable the compromised identity, and initiate an incident response
  • B. Rotate only the affected user's password
  • C. Wait for evidence of data access
  • D. Disable the service accounts and continue monitorin

Answer: A


NEW QUESTION # 26
Which Google Cloud log source is MOST critical for detecting unauthorized IAM role changes?

  • A. Cloud DNS logs
  • B. VPC Flow Logs
  • C. Firewall Rules logs
  • D. Cloud Audit Logs - Admin Activity

Answer: D


NEW QUESTION # 27
You have noticed that a Google Security Operations (SecOps) detection rule that detects excessive network connections is triggering too frequently and creating too many false positive alerts. You want to improve the rule to reduce the noise without reducing the effectiveness of the rule. What change to the detection rule should you implement?

  • A. Assign a risk score in the YARA-L outcome: section to prioritize alerts more effectively in the alert queue.
  • B. Include a 10 minute timeframe for the same source and destination of network connections in the YARA-L match: section to aggregate the alerts.
  • C. Add a threshold in the YARA-L condition: section to ensure that the rule only alerts after a certain number of connections.
  • D. Update the YARA-L events: section to exclude the most common IP addresses involved in the network connection alerts to reduce the number of alerts.

Answer: C


NEW QUESTION # 28
Your company's risk management and compliance team requires regular reporting on compliance with industry standard control frameworks for a regulated business unit that continuously adds projects. You need to create a report that includes evidence of non-compliant resources found in this environment. How should you generate this report?

  • A. Run queries for the required controls using the Cloud Asset Inventory data stored in BigQuery. Schedule this report to run regularly.
  • B. Implement the built-in posture for the compliance framework within the Security Command Center (SCC) posture.
  • C. Run an audit using the compliance framework in Audit Manager. Export the evaluation for consumption by the second-line team.
  • D. Implement the control framework using Rego, and deploy this framework in Workload Manager. Schedule a regular report in Workload Manager.

Answer: B


NEW QUESTION # 29
You are writing a detection rule in Google Security Operations (SecOps) SIEM that sends a risk score to the alert. You have access to Google Threat Intelligence (GTI) data through your Google SecOps subscription. You need to ensure that the threat score output in the detection logic informs the alert's risk score and is available for future detections. What should you do?

  • A. Configure a feed in Google SecOps SIEM to ingest GTI data to automatically enrich the appropriate entities.
  • B. Use the outcomes section of your detection logic to pull UDM enrichment fields from the event data. Apply logic to determine the total risk outcome, and store the risk score as the risk_score variable
  • C. Create a Google SecOps SOAR playbook to query GTI that uses the VirusTotal integration to enrich the alert. Modify the risk_score context value to match.
  • D. Use the match section of your detection logic to filter out irrelevant entities. Store the remaining entities as the risk_score variable.

Answer: B


NEW QUESTION # 30
Your organization uses Google Security Operations (SecOps) for security analysis and investigation. Your organization has decided that all security cases related to Data Loss Prevention (DLP) events must be categorized with a defined root cause specific to one of five DLP event types when the case is closed in Google SecOps. How should you achieve this?

  • A. Customize the Close Case dialog and add the five DLP event types as root cause options.
  • B. Customize the Case Name format to include the DLP event type.
  • C. Create a Google SecOps SOAR playbook that automatically assigns case tags where each tag contains the unique definition of one of the five DLP event types.
  • D. Create case tags in Google SecOps SOAR where each tag contains a unique definition of each of the five DLP event types, and have analysts assign them to cases manually.

Answer: A


NEW QUESTION # 31
Your company requires PCI DSS v4.0 compliance for its cardholder data environment (CDE) in Google Cloud. You use a Security Command Center (SCC) security posture deployment based on the PCI DSS v4.0 template to monitor for configuration drift. This posture generates a finding indicating that a Compute Engine VM within the CDE scope has been configured with an external IP address. You need to take an immediate action to remediate the compliance drift identified by this specific SCC posture finding. What should you do?

  • A. Navigate to the underlying Security Health Analytics (SHA) finding for PUBLIC_IP_ADDRESSon the VM, and mark this finding as fixed.
  • B. Reconfigure the network interface settings for the VM to explicitly remove the assigned external IP address.
  • C. Enable and enforce theconstraints/compute.vmExternallpAccess organization policy constraint at the project level for the project where the VM resides.
  • D. Remove the CDE-specific tag from the VM to exclude the tag from this particular PCI DSS posture evaluation scan.

Answer: B


NEW QUESTION # 32
Your organization uses the curated detection rule set in Google Security Operations (SecOps) for high priority network indicators. You are finding a vast number of false positives coming from your on-premises proxy servers. You need to reduce the number of alerts. What should you do?

  • A. Configure a rule exclusion for the target.ip field.
  • B. Configure a rule exclusion for the network.asset.ip field.
  • C. Configure a rule exclusion for the principal.ip field.
  • D. Configure a rule exclusion for the target.domain field.

Answer: B


NEW QUESTION # 33
You are investigating whether an advanced persistent threat (APT) actor has operated in your organization's environment undetected. You have received threat intelligence that includes:
- A SHA256 hash for a malicious DLL
- A known command and control (C2) domain
- A behavior pattern where rundll32.exe spawns powershell.exe with obfuscated arguments Your Google Security Operations (SecOps) instance includes logs from EDR, DNS, and Windows Sysmon. However, you have recently discovered that process hashes are not reliably captured across all endpoints due to an inconsistent Sysmon configuration. You need to use Google SecOps to develop a detection mechanism that identifies the associated activities. What should you do?

  • A. Write a multi-event YARA-L detection rule that correlates the process relationship and hash, and run a retrohunt based on this rule.
  • B. Create a single-event YARA-L detection rule based on the file hash, and run the rule against historical and incoming telemetry to detect the DLL execution.
  • C. Build a reference list that contains the hash and domain, and link the list to a high-frequency rule for near real-time alerting.
  • D. Use Google SecOps search to identify recent uses of rundll32.exe, and tag affected assets for watchlisting.

Answer: A


NEW QUESTION # 34
You are a security engineer at a managed security service provider (MSSP) that is onboarding to Google Security Operations (SecOps). You need to ensure that cases for each customer are logically separated. How should you configure this logical separation?

  • A. In Google SecOps SOAR settings, create a role for each customer.
  • B. In Google SecOps SOAR settings, create a new environment for each customer.
  • C. In Google SecOps SOAR settings, create a permissions group for each customer.
  • D. In Google SecOps Playbooks, create a playbook for each customer.

Answer: B


NEW QUESTION # 35
You are tasked with building a workflow in Google Security Operations (SecOps) SOAR. The documentation you are using requires a logical split that has eight different possible paths. You need to break the workflow into eight separate workflows using an automatic and efficient approach. What should you do?

  • A. Create a playbook that uses a Multi-Choice Question answer choices. Add instructions describing which logic to use in the instruction or question fields. Have the analyst select the appropriate answer to move the flow into the right branch.
  • B. Create eight playbooks for each workflow. Create a job that identifies your recently opened cases, applies the needed logic to determine which of the eight workflows should be attached, and attaches that workflow to the alert.
  • C. Create eight playbooks for each workflow. Configure the triggered playbook to end on an instruction action that tells the analyst to pick a workflow from the playbooks tab and attach that workflow to the alert.
  • D. Create a playbook that uses a flow condition. Add four more branches to have a total of five branches and an "Else" branch. On the "Else" branch, include another flow condition. Include the remaining three branches with the logic required.

Answer: D


NEW QUESTION # 36
You need to augment your organization's existing Security Command Center (SCC) implementation with additional detectors. You have a list of known IOCS and would like to include external signals for this capability to ensure broad detection coverage. What should you do?

  • A. Create a custom posture for your organization that combines the prebuilt Event Threat Detection and Security Health Analytics (SHA) detectors.
  • B. Create a custom log sink with internal and external IP addresses from threat intelligence. Use the SCC API to generate a finding for each event.
  • C. Create a Security Health Analytics (SHA) custom module using the compute address resource.
  • D. Create an Event Threat Detection custom module using the "Configurable Bad IP" template.

Answer: D


NEW QUESTION # 37
You are a security operations engineer in an enterprise that uses Google Security Operations (SecOps). Your organization recently faced a cybersecurity breach. You need to increase the threat analytics as quickly as possible. What should you do?

  • A. Enable curated detections to identify threats.
  • B. Ingest data from a threat intelligence platform (TIP) into Google SecOps.
  • C. Develop YARA-L detection rules that focus on threat intelligence.
  • D. Design YARA-L detection rules based on Google SecOps Marketplace use cases.

Answer: A


NEW QUESTION # 38
Your organization uses Google Security Operations (SecOps). You need to identify the most commonly occurring processes and applications across your organization's large number of servers so you can implement baselines and exclusion lists on a regular basis. You want to use the most efficient approach. What should you do?

  • A. Generate a Google SecOps SIEM dashboard based on relevant UDM fields, such as processes, that provides the counts for process names and files.
  • B. Use the UDM lookup feature to identify relevant process- related UDM fields and values.
  • C. Run a UDM search, and review aggregations for relevant process-related UDM fields.
  • D. Review the Google SecOps SIEM Rules & Detections, and identify the most common processes appearing in alerts that are marked as false positives.

Answer: C


NEW QUESTION # 39
......

Pass Google Cloud Certified GCP-SOE-B Exam With 87 Questions: https://www.suretorrent.com/GCP-SOE-B-exam-guide-torrent.html